S.01Cloud benchmark

AWS and Azure cloud penetration testing benchmark

AWS and Azure cloud penetration testing benchmark, real results only: AWS S3 bucket exploitation, Azure Key Vault pentest and Entra ID ROPC MFA bypass, and GCP SSRF metadata token theft, each run autonomously and proven with a working exploit.

97
cloud vulnerabilities
8
labs
45
proved with a real exploit

Darkmoon, the open source autonomous AI penetration testing tool, found 97 cloud vulnerabilities across 8 labs and proved 45 of them with a real exploit. The runs used AWS, Azure and GCP training labs; the model tokenizes real values through the Privacy Gateway so it works on placeholders.

S.04Results
Cloud runs, finding by finding

Each row links to its long-form write-up and to the raw report in the research corpus.

Lab / targetFindingsSeverityExploitedModelEvidence
AWS · huge-logistics S3camp_20260802_03bfc67595C1H2M1L5claude-opus-4-6Write-upReport
AWS · pwnedlabs EBS/S3camp_20260802_611cece192H5M2L0claude-opus-4-6Write-upReport
Azure · Entra ID tenantcamp_20260802_7eee391f2811C10H4M3L12claude-opus-4-6Write-upReport
Azure · BloodHound / priv-esccamp_20260802_9d245c0c198C6H5M11claude-opus-4-6Write-upReport
Azure · Key Vault (extract)camp_20260802_38118fb8162C6H8M6claude-opus-4-6Write-upReport
Azure · Key Vault (pivot)camp_20260802_59e4e90573C2H2M4claude-opus-4-6Write-upReport
GCP · SSRF to metadatacamp_20260802_656007d343C1H3claude-opus-4-6Write-upReport
GCP · public GCS bucketcamp_20260802_3ced719653C1H1M4claude-opus-4-6Write-upReport

Disclaimer
Darkmoon's own benchmark on public cloud training labs.

The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.

S.07FAQ
Cloud benchmark questions

What does the AWS and Azure cloud penetration testing benchmark cover?

Eight autonomous cloud runs across AWS, Azure and GCP: AWS S3 bucket exploitation to an IAM credential chain, Azure Key Vault pentest and Entra ID ROPC MFA bypass to tenant takeover paths, and GCP SSRF metadata token theft. Each run is published with the exact command per finding.

How many cloud vulnerabilities did Darkmoon find?

Darkmoon, the open source autonomous AI penetration testing tool, found 97 cloud vulnerabilities across 8 labs and proved 45 of them with a real exploit, from anonymous S3 listing to a PCI card-data dump and from a Key Vault secret to customer data.

Does the cloud benchmark keep my credentials off the model?

The open source Darkmoon CLI runs the assessment and its Privacy Gateway tokenizes real IPs, hosts and credentials so the model works on placeholders while the real values stay on your perimeter. The web dashboard and the remediation-to-PR loop are paid Pro capabilities.

S.08Next
Point Darkmoon at your own cloud

Open source, self hosted and local first. Run the same AWS, Azure and GCP checks on an account you own. A star helps other teams find it.